CVE-2024-20436: Null Pointer Dereference
A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20436?
CVE-2024-20436 has a high severity rating due to its potential impact causing denial of service conditions.
How do I fix CVE-2024-20436?
To mitigate CVE-2024-20436, update the Cisco IOS XE Software to a fixed release as outlined in Cisco's security advisory.
Which versions of Cisco IOS XE are affected by CVE-2024-20436?
CVE-2024-20436 affects multiple versions of Cisco IOS XE, including versions 3.9.0as to 17.12.1a.
Is authentication required to exploit CVE-2024-20436?
No, CVE-2024-20436 can be exploited by an unauthenticated remote attacker.
What type of vulnerability is CVE-2024-20436?
CVE-2024-20436 is a denial of service (DoS) vulnerability associated with a null pointer dereference.